Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
197 commits
Select commit Hold shift + click to select a range
b433d01
regen signature on allowed_signers file
djmdjm Apr 14, 2026
f2da673
Match case with other messages.
daztucker Apr 16, 2026
b6d4655
account newer openssl versions in .github/setup_ci.sh
quarckster Mar 16, 2026
713ec5c
Test against OpenSSL 3.6.2, 4.0.0 and 4.0-stable.
daztucker Apr 16, 2026
eb34f95
Make ci work for OpenSSL 4 variants
bob-beck Apr 16, 2026
00d955c
upstream: want stdint.h here now that we've switched from u_intXX_t
djmdjm Apr 7, 2026
ca19b95
upstream: Also show the duration of the current session through the
job Apr 13, 2026
45b30e0
upstream: correctly set extended type for client-side channels.
djmdjm Apr 19, 2026
7235471
Check for OPENSSL_NO_ENGINE for --with-ssl-engine.
daztucker Apr 25, 2026
1afbd7b
Re-enable SHA1 sigs in OpenSSL on Cygwin for tests.
daztucker Apr 27, 2026
8751cd9
Add tests for libressl-4.3.1.
daztucker Apr 20, 2026
ba110a5
Allow setting TEST_SSH_TRACE via Github.
daztucker Apr 20, 2026
6c5235c
Reorder steps to change perms before displaying.
daztucker Apr 20, 2026
4e0d1ae
Simplify Cygwin permissions setting.
daztucker Apr 20, 2026
b41203e
Comment out new PAM valgrind test until debugged.
daztucker Apr 27, 2026
2be9cec
Update OpenSSL tested versions.
daztucker Apr 27, 2026
ff254f6
upstream: Drop -Winline from CDIAGFLAGS it breaks on sparc64
cjeker Apr 23, 2026
2029edd
upstream: Use supported hostkeyalgorithms specifically in
daztucker Apr 27, 2026
6185d1e
Rename obsd arm64 snapshot VM for consistency.
daztucker Apr 27, 2026
b9ccca0
Add tracking for 10.3 branch.
daztucker Apr 28, 2026
f24dc9e
upstream: Clarify comment on what setting extended types for
job Apr 20, 2026
1bfe4ce
upstream: unveil the actual listening socket path and its directory
djmdjm Apr 28, 2026
1c553a1
upstream: fiddle with mask after umask call and not before; avoids
djmdjm Apr 29, 2026
7ab5e40
vm.yml: fix solaris PAM tests
renaudallard Mar 21, 2026
5fa60ae
Remove 9.9 and 10.0 branches from build status page.
daztucker Apr 30, 2026
328993c
skip ("#if 0") strvisx and stravis
djmdjm May 4, 2026
cb654c2
Add RUN_ONLY_PLATFORM to run a subset of tests.
daztucker May 4, 2026
05af655
Add Solaris 11.4-clang-19 test.
daztucker May 4, 2026
f9d62ea
Only run t-exec when re-testing with PAM.
daztucker May 4, 2026
6296749
Improve Solaris PAM tests.
daztucker May 4, 2026
a05de3f
Update to FreeBSD 14.4, add 15.0.
daztucker May 4, 2026
504d01d
Improve FreeBSD PAM tests.
daztucker May 4, 2026
4ea08a0
Improve NetBSD PAM tests.
daztucker May 4, 2026
3754f2e
upstream: classify dynamic-tcpip channels as bulk, not interactive;
djmdjm May 5, 2026
ac4a412
upstream: unbreak; spotted by Darren's test army
djmdjm May 5, 2026
56e73cd
ci: avoid rsync dependency in NetBSD VM jobs
Komzpa May 9, 2026
67f31ce
update getrrsetbyname.c from OpenBSD upstream
djmdjm May 12, 2026
ded80eb
Add VM test versions for : OmniOS and FreeBSD.
daztucker May 12, 2026
99f1e0c
OmniOS: check for gcc before installing.
daztucker May 12, 2026
6d9116d
Handle missing packages for FreeBSD 12.4.
daztucker May 12, 2026
55df196
Retire OmniOS r151046 & r151054 test configs.
daztucker May 12, 2026
cf6c0b3
upstream: fix hard-to-reach NULL deref during pubkey auth
djmdjm May 13, 2026
3339202
upstream: avoid validating bad cipher or mac lists in config files
djmdjm May 13, 2026
62fce76
upstream: chacha: avoid -Wunterminated-string-initialization
botovq May 18, 2026
e5c9cf9
upstream: mention usefulness of request type allow/denylisting for
djmdjm May 21, 2026
a5a1b7e
upstream: mention that compression could potentially leak
djmdjm May 21, 2026
18b9db7
Add interop tests against Dropbear >= 2020.79
daztucker May 19, 2026
4983725
Use backticks for shell portability w/ Solaris.
daztucker May 21, 2026
d0d7981
Another shell portability fix for Solaris.
daztucker May 21, 2026
6684776
Add OpenBSD 7.9 test VM.
daztucker May 21, 2026
42b213c
Fix IPTOS_DSCP_VA fallback
michaelforney May 21, 2026
3468ac7
Hardenedmalloc needs -std=c23 so build with clang.
daztucker May 25, 2026
0a561f9
Run hardenedmalloc test on ubuntu-latest.
daztucker May 26, 2026
0e2db7b
upstream: Fix skip message.
daztucker May 4, 2026
0cadf7e
upstream: Dropbear recently added a -Q option;
daztucker May 12, 2026
f44f124
upstream: Test all mutually supported algorithms,
daztucker May 27, 2026
7fbe3e4
upstream: add a -V flag to print the version, but mostly as a way
djmdjm May 27, 2026
3a05a07
upstream: use "ssh-agent -V" to test the binary is functional after
djmdjm May 27, 2026
26a8c13
upstream: ssh-agent: add -V to usage()
botovq May 27, 2026
3bee4a1
upstream: ssh: use sentinel idiom for timegm(3) and mktime(3)
botovq May 27, 2026
1690822
upstream: Use the new RELINK feature in bsd.prog.mk to build the
May 27, 2026
4f4aeee
sandbox-seccomp-filter: remove duplicate SC_ALLOW(__NR_clock_gettime64)
manfred-kaiser May 24, 2026
7ab700f
Make failure to set SECCOMP or NO_NEW_PRIVS fatal
djmdjm May 30, 2026
9d4c0b3
upstream: Replace the old recursive match_pattern() with an
djmdjm May 31, 2026
1e82d2c
upstream: fix client use-after-free on error path if cipher_init()
djmdjm May 31, 2026
10f66b2
upstream: Enforce a maximum size for usernames in agent key use
djmdjm May 31, 2026
26cde4c
upstream: stricter validation of the transport state passed from
djmdjm May 31, 2026
72b05ec
upstream: make the transport protocol stricter by disconnecting if
djmdjm May 31, 2026
8dfe7ed
upstream: DisableForwarding=yes didn't override PermitTunnel=yes
djmdjm May 31, 2026
073faa6
upstream: Fix two separate one-byte out-of-cound reads
djmdjm May 31, 2026
5a5e477
upstream: disallow use of the copy-data extension to read and write
djmdjm May 31, 2026
df18979
upstream: DNS0x20[1] can randomise the case of domain names returned by
djmdjm May 31, 2026
a1dd1c8
upstream: avoid strlen(NULL) crash if an X11 channel was created before
djmdjm May 31, 2026
bebc855
upstream: big refactor of sshd config management code.
djmdjm May 31, 2026
633a4c1
upstream: flesh out match_pattern() tests, including a new
djmdjm May 31, 2026
f2b815e
upstream: the new configuration dump code emits configuration
djmdjm May 31, 2026
3bc4ac4
upstream: unit test for new servconf.[ch] code, including a basic
djmdjm May 31, 2026
ea91c7a
depend
djmdjm May 31, 2026
58b9381
upstream: handle compiled-time unsupported options in servconf.h
djmdjm May 31, 2026
de24573
upstream: Actually set pollfd.events correctly for socket type
djmdjm Jun 1, 2026
684d26a
upstream: sk-usbhid: skip unsupported key types in read_rks()
djmdjm Jun 1, 2026
7b77606
Update LibreSSL test 4.3.1->4.3.2.
daztucker Jun 1, 2026
2afcdf7
Pass awk detected by configure to regress tests.
daztucker Jun 1, 2026
51db029
Don't install shim for AWK=awk.
daztucker Jun 1, 2026
de97e5a
upstream: differentiate between execution failures and subsystem not
djmdjm Jun 1, 2026
e8c12cc
setup_ci.sh: add timeout and allow one retry
daztucker Jun 1, 2026
14d88d4
Add includes.h for compat functions.
daztucker Jun 2, 2026
41bb8c1
Add a single retry to VM package install steps.
daztucker Jun 2, 2026
7e5590c
Replace shell-level timeout with dedicated command.
daztucker Jun 2, 2026
60343e4
Fix search for awk formatter.
daztucker Jun 2, 2026
c9ebebb
Reformat setup_ci command line.
daztucker Jun 2, 2026
65c6ac0
upstream: refer to RFC9987 instead of I-D
djmdjm Jun 2, 2026
7763a38
upstream: add signature malleability and pubkey validity checks to
djmdjm Jun 4, 2026
37bf143
upstream: rename a variable to be more accurate
djmdjm Jun 5, 2026
70d7044
upstream: avoid truncation of pathnames headed to lstat() for
djmdjm Jun 5, 2026
e9916c4
upstream: pass >9 commandline arguments to the internal-sftp server,
djmdjm Jun 5, 2026
47af21e
sync fmt_scaled.c with OpenBSD upstream
djmdjm Jun 6, 2026
5ebfdf3
upstream: Import updated moduli
daztucker Jun 7, 2026
5af8f3f
upstream: Make crypto_sign_ed25519_keypair_from_seed()
daztucker Jun 7, 2026
b7e5521
upstream: when replying to a "query" SSH_AGENTC_EXTENSION request,
djmdjm Jun 13, 2026
81ca145
upstream: Add experimental support for a composite post-quantum
djmdjm Jun 14, 2026
db1bad1
upstream: make crypto_sign_ed25519_keypair_from_seed non-static.
djmdjm Jun 14, 2026
5a474d1
upstream: unit and regression tests for composite PQ ML-DSA44/Ed25519
djmdjm Jun 14, 2026
8e0cb47
hook up new regress/unittests/crypto
djmdjm Jun 14, 2026
ea505c8
provide a htobe32() replacement
djmdjm Jun 14, 2026
1c46384
include includes.h
djmdjm Jun 14, 2026
b35a6a1
don't build ML-KEM/ML-DSA code with <C99 compilers
djmdjm Jun 14, 2026
ebdaacf
bring back mlkem768x25519-sha256 stubs
djmdjm Jun 15, 2026
1d6064d
upstream: fix multiple problems with testing hostkey types that are not
djmdjm Jun 15, 2026
f5f02aa
another place mldsa-ed25519 keys need deactivation
djmdjm Jun 15, 2026
860ed04
upstream: avoid use of paste(1); helps portable
djmdjm Jun 15, 2026
f433c09
upstream: use different strategy to check whether keys are present or
djmdjm Jun 15, 2026
61ca39c
Remove check for OpenSSL w/out AES192/256.
daztucker Jun 16, 2026
3de49e0
upstream: Include stdlib.h for malloc/free and sort headers.
daztucker Jun 16, 2026
60978dd
upstream: Include stdarg.h for va_list (needed for xmalloc.h).
daztucker Jun 16, 2026
b9d134a
upstream: Use awk instead of cut to help -portable.
daztucker Jun 16, 2026
0d156d3
upstream: Factor out hex2bin into a shared helper function.
daztucker Jun 16, 2026
983096a
ci: pin GitHub Actions to full commit SHAs
XananasX7 Jun 3, 2026
faa646a
ci: pin upstream.yml actions to full commit SHAs
XananasX7 Jun 3, 2026
01404fa
Add script to lookup and pin Actions to hashes.
daztucker Jun 22, 2026
10715f2
Output Actions allowlist for uploading to Github.
daztucker Jun 22, 2026
0d08d38
upstream: remove cipher_set_keyiv() as nothing uses it from
djmdjm Jun 19, 2026
b88165a
upstream: annotate tm_wday = -1 with /* sentinel for error */ per
botovq Jun 21, 2026
e683097
upstream: Check return value of sscanf.
daztucker Jun 22, 2026
512bfed
upstream: Check return values from malloc.
daztucker Jun 22, 2026
5dac5a9
Set build options in /etc/mk.conf once at startup.
daztucker Jun 24, 2026
162cb87
upstream: add a missing channels type for bulk/interactive
djmdjm Jun 24, 2026
87e21b1
upstream: add some logging to make debugging interactive/bulk
djmdjm Jun 24, 2026
8058c5b
upstream: mention a caveat regarding GSSAPIStrictAcceptorCheck in
djmdjm Jun 24, 2026
110117a
Set CYGWIN at top-level.
daztucker Jun 24, 2026
a4c5d09
Make -j2 for faster builds.
daztucker Jun 24, 2026
7c70c3d
Fix handling of rh-allow-sha1-signatures on Cygwin
daztucker Jun 24, 2026
aa60cf3
upstream: Avoid printf("%s", NULL) since it's not guaranteed to be safe
daztucker Jun 24, 2026
b0894a2
Dropbear's master is now main.
daztucker Jun 24, 2026
6f74eb3
Dropbear master -> main here too.
daztucker Jun 24, 2026
09c2eeb
upstream: mention that ssh-keyscan output is only as trustworthy as
djmdjm Jun 26, 2026
8dec7df
upstream: avoid possible NULL deref; from Swival scanner
djmdjm Jun 28, 2026
3648018
upstream: resist that return ".." via remote glob during
djmdjm Jun 28, 2026
1b39f39
upstream: avoid download to server-controlled path when performing
djmdjm Jun 29, 2026
c1cebbc
upstream: avoid situation where sftp_download() could get stuck in
djmdjm Jun 29, 2026
c58b363
upstream: fix ECDSA order check for curves with cofactor != 1. All
djmdjm Jun 29, 2026
1cfbed8
upstream: Fix bounds checking when signing messages of length
djmdjm Jun 29, 2026
d6a589d
upstream: make ssh-add open it's connection to the agent after it
djmdjm Jun 29, 2026
8436559
upstream: don't print an error message when trying to load a host
djmdjm Jun 29, 2026
ef6bef3
fix leak of error path; GHPR681 from metsw24-max
djmdjm Jun 29, 2026
fa5416d
use size_t for lengths; GHPR681 from metsw24-max
djmdjm Jun 29, 2026
9d5238f
return result of raise(2); GHPR681 from metsw24-max
djmdjm Jun 29, 2026
fceb78d
check sockaddr length; GHPR681 from metsw24-max
djmdjm Jun 29, 2026
3655229
don't leak rrset on fail; GHPR681 from metsw24-max
djmdjm Jun 29, 2026
d9df26d
upstream: don't use deprecated ERR_load_crypto_strings()
djmdjm Jun 29, 2026
c871613
upstream: report errors in fill_default_options() properly, based on
djmdjm Jun 29, 2026
849748c
upstream: correct directive name (s/Host/Match) in error message
djmdjm Jun 29, 2026
ce697f1
upstream: mention RefuseConnection, VersionAddendum and
djmdjm Jun 29, 2026
3c3226f
upstream: move documentation of the Include directive to near the
djmdjm Jun 29, 2026
a9cb2e3
upstream: fix "ls -n", which was still displaying user/group names
djmdjm Jun 29, 2026
0eaedde
upstream: s/calloc/xcalloc/ to reduce noise from AI bug detectors
djmdjm Jun 29, 2026
5d8e429
upstream: check strdup() return to avoid NULL deref on failure.
djmdjm Jun 29, 2026
0875a78
upstream: fix ineffective max file size check when loading
djmdjm Jun 29, 2026
b9d2162
upstream: Move user/group name lookup to correct place; coverity
djmdjm Jun 29, 2026
23a7c4d
upstream: revert bits that weren't ready for commit yet
djmdjm Jun 29, 2026
fa447bd
upstream: check key and IV length received in privsep state
djmdjm Jun 30, 2026
710cd5a
upstream: set FD_CLOEXEC on the fds between sftp and its ssh
djmdjm Jun 30, 2026
dcba967
upstream: another ruser_name/ruser_group vs attrib_to_stat() ordering
djmdjm Jun 30, 2026
aabe6d2
upstream: ssherr-libcrypto: avoid use of deprecated
botovq Jun 30, 2026
fe85df4
upstream: mention mldsa44-ed25519 in usage(); based on GHPR695 from
djmdjm Jun 30, 2026
2963932
upstream: ssh -o doesn't support Host or Include options, they are only
djmdjm Jul 1, 2026
8b05bbe
upstream: Move negative-FD checks to before first use. CID 909998,
daztucker Jul 1, 2026
55ffd11
upstream: Tighten up the introduction a little:
djmdjm Jul 1, 2026
0cdead0
upstream: simplify SIGINFO output: remove list of active channels (too
djmdjm Jul 1, 2026
088ca00
upstream: whitespace
djmdjm Jul 1, 2026
654e1a3
upstream: more missing mldsa44-ed25519, based on GHPR696 from Loganaden
djmdjm Jul 1, 2026
0a75a95
Provide better error for non-supported private keys
ZoltanFridrich Apr 16, 2025
c53864f
Tabs -> spaces.
daztucker Jun 25, 2026
a5ecfdc
Need clang >= 19 for constexpr in hardened_malloc.
daztucker Jul 2, 2026
85dcff2
revise README.privsep for multi-binary model
djmdjm Jul 3, 2026
01ed1c6
tweak previous
djmdjm Jul 3, 2026
f80e654
tweak; from dlg@
djmdjm Jul 3, 2026
3912be7
more README.privsep polish
djmdjm Jul 3, 2026
c123ac1
more config option details in README.privsep
djmdjm Jul 3, 2026
aab5620
grammar fix; from Daniel O'Connor
djmdjm Jul 3, 2026
93d6348
upstream: fix inverted test that broke ssh-add with keys on stdin. From
djmdjm Jul 5, 2026
cf67d46
upstream: void functions should not return anything. Patch from Tim
daztucker Jul 5, 2026
d43ba60
upstream: Fix cases in GSSAPI and keyboard-interactive
djmdjm Jul 6, 2026
e8bdfb1
upstream: fix ownership and lifetime of several bits of client
djmdjm Jul 6, 2026
5d04ca6
upstream: Fix multiple RFC 4462 (GSSAPIAuthentication) compliance
djmdjm Jul 6, 2026
0210c7c
upstream: openssh-10.4
djmdjm Jul 6, 2026
0227fe4
crank version numbers
djmdjm Jul 6, 2026
449d25b
depend
djmdjm Jul 6, 2026
e8dd756
autogenerated files for release
djmdjm Jul 6, 2026
823ad00
upstream: fix GSSAPI option names, that I somehow screwed up while
djmdjm Jul 7, 2026
6789420
Re-allow PAMServiceName inside a Match block.
daztucker Aug 6, 2026
54ef3d4
Merge remote-tracking branch 'openssh/V_10_4' into feature/openssh_10…
andrewyounkers Aug 10, 2026
1dc4dc1
merge conflict resolutions
andrewyounkers Aug 10, 2026
1ef3c3a
update readme to include OpenSSH 'ssh-mldsa44-ed25519' implementation
andrewyounkers Aug 10, 2026
11d631a
address regression failures
andrewyounkers Aug 10, 2026
5e43328
bring in applicable openssh changes to vm.yml
andrewyounkers Aug 10, 2026
31f2cc0
Prefer OpenSSH implementations of supported hybrid KEX algorithms
andrewyounkers Aug 25, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion .depend

Large diffs are not rendered by default.

35 changes: 35 additions & 0 deletions .github/install_dropbear.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
#!/bin/sh
#
# Install specified Dropbear version into /usr/local.
#

ver="$1"

echo
echo ---------------------------------------------
echo Installing dropbear version: ${ver}
echo ---------------------------------------------

set -e

cd /tmp

if [ ! -d dropbear-clean ]; then
git clone https://github.com/mkj/dropbear.git dropbear-clean
(cd dropbear-clean && git config --global advice.detachedHead false)
fi

rm -rf dropbear
cp -a dropbear-clean dropbear
cd dropbear
git checkout "$ver"
git status
echo "Building Dropbear version '$ver'"
(
autoreconf 2>&1 &&
./configure 2>&1 &&
make clean 2>&1 &&
make 2>&1 &&
sudo make install 2>&1) >/tmp/db-build.log 2>&1 || cat /tmp/db-build.log

echo "Installed dropbear version: '$(/usr/local/bin/dbclient -V 2>&1)'"
2 changes: 1 addition & 1 deletion .github/install_libcrypto.sh
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ if [ "${abi_compat_test}" = "y" ]; then
ver="${major}.$((${minor} + 1))"
echo selecting next release branch ${ver}
;;
openssl-3.*.*)
openssl-[34].*.*)
major=$(echo ${ver} | cut -f1 -d.)
minor=$(echo ${ver} | cut -f2 -d.)
patch=$(echo ${ver} | cut -f3 -d.)
Expand Down
35 changes: 35 additions & 0 deletions .github/pin_actions.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
#!/bin/sh
#
# Look up specified version of Github Actions an pin to that specific
# revision.
#

set -e

github=https://github.com

for workflow in workflows/*.yml; do
sed 's/ - / /' ${workflow} | grep -v '^#' | awk '/uses:/ {print}' | \
while read line; do
action_ver=$(awk '{print $2}' <<<${line})
action=$(cut -f1 -d@ <<<${action_ver})
ver=$(cut -f2 -d@ <<<${action_ver})
intendedver=$(awk '{print $4}' <<<${line})
if [ -z "${intendedver}" ]; then
intendedver=${ver}
fi
case "${action}" in
google/oss-fuzz/*) actiondir=google/oss-fuzz ;;
*) actiondir="${action}" ;;
esac
if [ ! -d /tmp/${actiondir} ]; then
git clone ${github}/${actiondir} /tmp/${actiondir}
fi
hash=$(cd /tmp/${actiondir} && git rev-parse ${intendedver})
sed -i -e "s|uses: ${action}@.*|uses: ${action}@${hash} # ${intendedver}|" \
${workflow}
done
done

# Output actions for allowlist.
awk 'BEGIN{IFS=":"} /^ +uses:.*@/{print $2","}' workflows/*.yml | sort -u
95 changes: 54 additions & 41 deletions .github/workflows/vm.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,11 +2,7 @@
# Security -> Actions -> Variables) to restrict the tests that are run
# The supported variables are:
#
# RUN_ONLY_TARGET_CONFIG: Run only the single matching target and config,
# separated by spaces, eg "ubuntu-latest default". All other tests will
# fail immediately.
#
# LTESTS: Override the set of tests run.
# RUN_ONLY_PLATFORM: run only tests on specified platform.

name: CI VM
on:
Expand All @@ -18,7 +14,7 @@ on:
jobs:
dragonflybsd:
name: "dragonflybsd-${{ matrix.target }}"
if: github.repository != 'openssh/openssh-portable-selfhosted'
if: github.repository != 'openssh/openssh-portable-selfhosted' && (vars.RUN_ONLY_PLATFORM == '' || vars.RUN_ONLY_PLATFORM == 'dragonflybsd')
strategy:
fail-fast: false
matrix:
Expand All @@ -27,10 +23,10 @@ jobs:
config: [default]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@main
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # main

- name: start DragonFlyBSD ${{ matrix.target }} VM
uses: vmactions/dragonflybsd-vm@v1
uses: vmactions/dragonflybsd-vm@4ba8127bd95c94b66fc4b885e37c99955ba308ea # v1
with:
release: ${{ matrix.target }}
usesh: true
Expand Down Expand Up @@ -67,21 +63,21 @@ jobs:

freebsd:
name: "freebsd-${{ matrix.target }}"
if: github.repository != 'openssh/openssh-portable-selfhosted'
if: github.repository != 'openssh/openssh-portable-selfhosted' && (vars.RUN_ONLY_PLATFORM == '' || vars.RUN_ONLY_PLATFORM == 'freebsd')
strategy:
fail-fast: false
matrix:
target:
- "13.5"
- "14.3"
# - "15.0" # "pkg" breaks with a libutil.so error...
- "14.4"
- "15.0"
config: [default]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@main
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # main

- name: start FreeBSD ${{ matrix.target }} VM
uses: vmactions/freebsd-vm@v1
uses: vmactions/freebsd-vm@b84ab5559b5a1bb4b8ee2737d2506a16e1737636 # v1
with:
release: ${{ matrix.target }}
usesh: true
Expand All @@ -108,15 +104,15 @@ jobs:
sudo -u builder env VMCI=true WITH_OPENSSL=true bash ./oqs-scripts/build_openssh.sh
- name: Run tests documented to pass
shell: freebsd {0}
run: cd $GITHUB_WORKSPACE && sudo -u builder bash ./oqs-test/run_tests.sh
run: cd $GITHUB_WORKSPACE && sudo -u builder env SKIP_LTESTS=scp3 bash ./oqs-test/run_tests.sh
- name: Ensure we have the ssh and sshd syntax right once for each algorithm
shell: freebsd {0}
run: cd $GITHUB_WORKSPACE && sudo -u builder python3 oqs-test/try_connection.py doone


netbsd:
name: "netbsd-${{ matrix.target }}"
if: github.repository != 'openssh/openssh-portable-selfhosted'
if: github.repository != 'openssh/openssh-portable-selfhosted' && (vars.RUN_ONLY_PLATFORM == '' || vars.RUN_ONLY_PLATFORM == 'netbsd')
strategy:
fail-fast: false
matrix:
Expand All @@ -129,13 +125,15 @@ jobs:
config: [default]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@main
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # main

- name: start NetBSD ${{ matrix.target }} VM
uses: vmactions/netbsd-vm@v1
uses: vmactions/netbsd-vm@99816dccf75edf233ed6cd00a159e3a5b85ea373 # v1
with:
release: ${{ matrix.target }}
usesh: true
sync: scp
copyback: false
prepare: |
/usr/sbin/pkg_add -U autoconf automake bash cmake git ninja-build pcre2 python311 sudo
/usr/sbin/useradd -m builder
Expand Down Expand Up @@ -167,8 +165,7 @@ jobs:
run: |
cd $GITHUB_WORKSPACE
/sbin/chown -R builder .
sed 's/SKIPPED_DUE_TO_CERTIFIED_KEYS}"/SKIPPED_DUE_TO_CERTIFIED_KEYS} ssh-tty"/' \
./oqs-test/run_tests.sh | sudo -u builder bash
sudo -u builder env SKIP_LTESTS=ssh-tty bash ./oqs-test/run_tests.sh
- name: Ensure we have the ssh and sshd syntax right once for each algorithm
shell: netbsd {0}
run: |
Expand All @@ -179,27 +176,27 @@ jobs:

omnios:
name: "omnios-${{ matrix.target }}"
if: github.repository != 'openssh/openssh-portable-selfhosted'
if: github.repository != 'openssh/openssh-portable-selfhosted' && (vars.RUN_ONLY_PLATFORM == '' || vars.RUN_ONLY_PLATFORM == 'omnios')
strategy:
fail-fast: false
matrix:
target:
- "r151054"
- "r151046"
- "r151056-build"
- "r151058-build"
config: [default]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@main
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # main

- name: start OmniOS ${{ matrix.target }} VM
uses: vmactions/omnios-vm@v1
uses: vmactions/omnios-vm@7f2be0b927aad1a78498c8aeeac4c4ce1fabd322 # v1
with:
release: ${{ matrix.target }}
usesh: true
prepare: |
set -x
pfexec pkg refresh
pfexec pkg install autoconf automake bash build-essential cmake git ninja runtime/python-311
pfexec pkg install autoconf automake bash build-essential cmake git ninja runtime/python-313
useradd -m builder
sed -e "s/^root.*ALL$/root ALL=(ALL) NOPASSWD: ALL/" /etc/sudoers >>/tmp/sudoers
mv /tmp/sudoers /etc/sudoers
Expand Down Expand Up @@ -240,7 +237,7 @@ jobs:

openbsd:
name: "openbsd-${{ matrix.target }}"
if: github.repository != 'openssh/openssh-portable-selfhosted'
if: github.repository != 'openssh/openssh-portable-selfhosted' && (vars.RUN_ONLY_PLATFORM == '' || vars.RUN_ONLY_PLATFORM == 'openbsd')
strategy:
fail-fast: false
matrix:
Expand All @@ -250,13 +247,14 @@ jobs:
# - "7.6"
- "7.7"
- "7.8"
- "7.9"
config: [default]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@main
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # main

- name: start OpenBSD ${{ matrix.target }} VM
uses: vmactions/openbsd-vm@v1
uses: vmactions/openbsd-vm@18edb32f4e48dae5865d7b8b3a9587bc01218a20 # v1
with:
release: ${{ matrix.target }}
usesh: true
Expand Down Expand Up @@ -299,8 +297,7 @@ jobs:
run: |
cd $GITHUB_WORKSPACE
chown -R builder .
sed 's/SKIPPED_DUE_TO_CERTIFIED_KEYS}"/SKIPPED_DUE_TO_CERTIFIED_KEYS} ssh-tty"/' \
./oqs-test/run_tests.sh | doas -u builder bash
doas -u builder env SKIP_LTESTS=ssh-tty bash ./oqs-test/run_tests.sh
- name: Ensure we have the ssh and sshd syntax right once for each algorithm
shell: openbsd {0}
run: |
Expand All @@ -312,15 +309,15 @@ jobs:
openbsd-current-upstream:
# This job runs the OQS workflow against OpenBSD -current.
name: "openbsd-current-upstream"
if: github.repository != 'openssh/openssh-portable-selfhosted'
if: github.repository != 'openssh/openssh-portable-selfhosted' && (vars.RUN_ONLY_PLATFORM == '' || vars.RUN_ONLY_PLATFORM == 'openbsd')
strategy:
fail-fast: false
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@main

- name: start OpenBSD VM
uses: vmactions/openbsd-vm@v1
uses: vmactions/openbsd-vm@18edb32f4e48dae5865d7b8b3a9587bc01218a20 # v1
with:
copyback: false
nat: |
Expand All @@ -337,13 +334,13 @@ jobs:
mkdir -p /var/empty /usr/local/etc
cp $GITHUB_WORKSPACE/moduli /usr/local/etc/moduli

- name: Fetch sysupgrade version
- name: fetch sysupgrade version
run: |
ver=$(curl -s https://cdn.openbsd.org/pub/OpenBSD/snapshots/amd64/BUILDINFO)
echo "SNAPSHOT_VERSION=${ver}" >> $GITHUB_ENV
- name: check for cached sysupgrade
id: cache-sysupgrade
uses: actions/cache@v4
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
with:
key: openbsd-sysupgrade ${{ env.SNAPSHOT_VERSION }}
path: /tmp/_sysupgrade/
Expand All @@ -363,7 +360,7 @@ jobs:
rsync -av openbsd:/home/_sysupgrade/ /tmp/_sysupgrade/
- name: save sysupgrade to cache
if: steps.cache-sysupgrade.outputs.cache-hit != 'true'
uses: actions/cache/save@v4
uses: actions/cache/save@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
with:
key: openbsd-sysupgrade ${{ env.SNAPSHOT_VERSION }}
path: /tmp/_sysupgrade/
Expand Down Expand Up @@ -396,8 +393,7 @@ jobs:
run: |
cd $GITHUB_WORKSPACE
chown -R builder .
sed 's/SKIPPED_DUE_TO_CERTIFIED_KEYS}"/SKIPPED_DUE_TO_CERTIFIED_KEYS} ssh-tty"/' \
./oqs-test/run_tests.sh | doas -u builder bash
doas -u builder env SKIP_LTESTS=ssh-tty bash ./oqs-test/run_tests.sh
- name: Ensure we have the ssh and sshd syntax right once for each algorithm
shell: openbsd {0}
run: |
Expand All @@ -408,28 +404,45 @@ jobs:

solaris:
name: "solaris-${{ matrix.target }}"
if: github.repository != 'openssh/openssh-portable-selfhosted'
if: github.repository != 'openssh/openssh-portable-selfhosted' && (vars.RUN_ONLY_PLATFORM == '' || vars.RUN_ONLY_PLATFORM == 'solaris')
strategy:
fail-fast: false
matrix:
target:
- "11.4-gcc"
- "11.4-clang-19"
config: [default]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@main
- uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # main

- name: start Solaris ${{ matrix.target }} VM
uses: vmactions/solaris-vm@v1
uses: vmactions/solaris-vm@d30dd6c228c8661ade859e36ead7660b9a62efcc # v1
with:
release: ${{ matrix.target }}
usesh: true
prepare: |
set -x
packages=""
command -v autoconf >/dev/null 2>&1 || packages="$packages autoconf"
command -v automake >/dev/null 2>&1 || packages="$packages automake"
command -v git >/dev/null 2>&1 || packages="$packages git"
command -v ninja >/dev/null 2>&1 || packages="$packages ninja"
command -v python3.11 >/dev/null 2>&1 || packages="$packages runtime/python-311"
[ -z "$packages" ] || pkg install --no-backup-be --accept $packages
id -u builder >/dev/null 2>&1 || useradd -m builder
openssl rand -base64 9 >$GITHUB_WORKSPACE/regress/password
chown builder $GITHUB_WORKSPACE/regress/password
pw=$(tr -d '\n' <$GITHUB_WORKSPACE/regress/password | openssl passwd -6 -stdin)
passwd -p "$pw" builder
sed -e "s/^root.*ALL$/root ALL=(ALL) NOPASSWD: ALL/" /etc/sudoers >>/tmp/sudoers
mv /tmp/sudoers /etc/sudoers
echo "builder ALL=(ALL) NOPASSWD: ALL" >>/etc/sudoers
echo "builder ALL=(ALL) NOPASSWD: ALL" >/etc/sudoers.d/builder
echo 'Testing sudo config for root->builder.'
sudo -u builder id
echo 'Testing sudo config for builder->root.'
sudo -u builder sudo id
echo Creating directories.
mkdir -p /var/empty /usr/local/etc
cp $GITHUB_WORKSPACE/moduli /usr/local/etc/moduli

Expand Down
2 changes: 2 additions & 0 deletions .skipped-commit-ids
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,8 @@ da414a364c25b187fc686da7aacec2c35d29238a ssh-keygen, fixup'ed into 21682417
a05e13a7e2c0b65bb4b47184fef731243431c6ff Makefile.inc
7e8178786157e863f6ff63c5d55200d7b6b04f9e remove old sandbox files
98eefed432ff8253b307002e20d28da14b93e7e3 Makefile.inc
eb4169949bf61188fb7336b11b73833019d10d7b Makefile changes
df5c950444e208b320265fa8a1afd676e2edfa6e Makefile changes

Old upstream tree:

Expand Down
Loading